Mastodon Feed: Post

Mastodon Feed

Boosted by cwebber@social.coop ("Christine Lemmer-Webber"):
dazo@infosec.exchange ("🐈‍⬛David Sommerseth") wrote:

@bagder In OpenVPN we're seeing something similar, even though not as bad as Unbound. We haven't created any stats on severity, just looked at the numbers in general.

So far this year, we have as many CVE reports as we've had between 2023 and 2025 combined. And that's just the ones we concluded is really a CVE. Then comes all the false reports and other security reports just being a bug report in practice.

The vast majority of them this year are not really that critical in practice. But the CVSS scoring makes it sound like the world is crashing.

What is really eating up our time processing these reports is actually verifying that the claims are correct. Most of these reports are just too detailed, many adding lots of nonsense and actually make the report less valuable. The real issue drowns in false assumptions. Some reports stands out, of course, as pretty good. But the vast majority has really killed the fun.